CVE-2006-3018
Summary
| CVE | CVE-2006-3018 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-14 23:02:00 UTC |
| Updated | 2010-09-15 04:54:00 UTC |
| Description | Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Ubuntu update for PHP - Advisories - Secunia | SECUNIA | secunia.com | |
| SecurityTracker.com Archives - PHP Input Validation Hole Permits Cross-Site Scripting Attacks and Other Bugs Have Unspecified Impact | SECTRACK | securitytracker.com | |
| 25254 | OSVDB | www.osvdb.org | |
| usn/usn-320-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| PHP: PHP 5.1.3 Release Announcement | CONFIRM | www.php.net | |
| PHP Multiple Unspecified Vulnerabilities | BID | www.securityfocus.com | |
| PHP Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Mandriva update for php - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2006-09-20 | Mark J Cox | Unknown: CVE-2006-3018 has been assigned to an issue in PHP where the cause and fix are unknown, and the impact cannot be verified. The source of the CVE assignment was a single line statement in the PHP 5.1.3 release announcement, http://www.php.net/release_5_1_3.php, reading: "Fixed a heap corruption inside the session extension." Of the changes made to the session extension between releases 5.1.2 and 5.1.3, none would fix a bug matching this description by our analysis. |
There are currently no legacy QID mappings associated with this CVE.